| #!/bin/bash |
| |
| |
|
|
| set -euo pipefail |
|
|
| |
| SETTINGS_FILE=".claude/my-plugin.local.md" |
|
|
| |
| if [[ ! -f "$SETTINGS_FILE" ]]; then |
| |
| exit 0 |
| fi |
|
|
| |
| FRONTMATTER=$(sed -n '/^---$/,/^---$/{ /^---$/d; p; }' "$SETTINGS_FILE") |
|
|
| |
| ENABLED=$(echo "$FRONTMATTER" | grep '^enabled:' | sed 's/enabled: *//' | sed 's/^"\(.*\)"$/\1/') |
| STRICT_MODE=$(echo "$FRONTMATTER" | grep '^strict_mode:' | sed 's/strict_mode: *//' | sed 's/^"\(.*\)"$/\1/') |
| MAX_SIZE=$(echo "$FRONTMATTER" | grep '^max_file_size:' | sed 's/max_file_size: *//') |
|
|
| |
| if [[ "$ENABLED" != "true" ]]; then |
| exit 0 |
| fi |
|
|
| |
| input=$(cat) |
| file_path=$(echo "$input" | jq -r '.tool_input.file_path // empty') |
|
|
| |
| if [[ "$STRICT_MODE" == "true" ]]; then |
| |
| if [[ "$file_path" == *".."* ]]; then |
| echo '{"hookSpecificOutput": {"permissionDecision": "deny"}, "systemMessage": "Path traversal blocked (strict mode)"}' >&2 |
| exit 2 |
| fi |
|
|
| if [[ "$file_path" == *".env"* ]] || [[ "$file_path" == *"secret"* ]]; then |
| echo '{"hookSpecificOutput": {"permissionDecision": "deny"}, "systemMessage": "Sensitive file blocked (strict mode)"}' >&2 |
| exit 2 |
| fi |
| else |
| |
| if [[ "$file_path" == "/etc/"* ]] || [[ "$file_path" == "/sys/"* ]]; then |
| echo '{"hookSpecificOutput": {"permissionDecision": "deny"}, "systemMessage": "System path blocked"}' >&2 |
| exit 2 |
| fi |
| fi |
|
|
| |
| if [[ -n "$MAX_SIZE" ]] && [[ "$MAX_SIZE" =~ ^[0-9]+$ ]]; then |
| content=$(echo "$input" | jq -r '.tool_input.content // empty') |
| content_size=${#content} |
|
|
| if [[ $content_size -gt $MAX_SIZE ]]; then |
| echo '{"hookSpecificOutput": {"permissionDecision": "deny"}, "systemMessage": "File exceeds configured max size: '"$MAX_SIZE"' bytes"}' >&2 |
| exit 2 |
| fi |
| fi |
|
|
| |
| exit 0 |
|
|